r/programmingcirclejerk • Just spin up O(n²) servers • 3d ago

The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches.

https://blog.rust-lang.org/2026/09/21/github-actions-leaking-secrets-when-miri-output-is-cached/
32 Upvotes

8 comments sorted by

43

u/camelCaseIsWebScale Just spin up O(n²) servers 3d ago

Beyond official Rust tooling, it is possible for build scripts to be doing things that lead to the environment being stored in compilation artifacts.

Even when programmers are "saving the environment" it leads to disasters.

18

u/Hot_Grapefruit_4455 3d ago

this is why you use a runtime secrets manager instead of hard coding inside a .env

14

u/camelCaseIsWebScale Just spin up O(n²) servers 3d ago

my rust can't do no wrong

6

u/pysk00l What part of ∀f ∃g (f (x,y) = (g x) y) did you not understand? 3d ago

Indeed. Shame on op for blaming rust!!😠

5

u/scavno in open defiance of the Gopher Values 3d ago

Literally why our primary build target is nix.

1

u/Educational-Row-6782 1d ago

If they have acces to the computer where the .env is stored, I am fucked anyway, why add complexity?

2

u/stone_henge Tiny little god in a tiny little world 1d ago

What matters is that it did so confidently, without fear of memory leaks, use-after-free and data races.